fix: Perbaiki CORS middleware agar selalu add headers jika wildcard diizinkan, tambah script check_cors.php
This commit is contained in:
@@ -68,6 +68,12 @@ class CorsMiddleware implements MiddlewareInterface
|
||||
// Determine allowed origin
|
||||
$allowedOrigin = $this->getAllowedOrigin($origin);
|
||||
|
||||
// Always add CORS headers if wildcard is allowed (even if origin is empty)
|
||||
// This ensures CORS works for all requests
|
||||
if ($allowedOrigin === null && in_array('*', $this->allowedOrigins, true)) {
|
||||
$allowedOrigin = '*';
|
||||
}
|
||||
|
||||
if ($allowedOrigin) {
|
||||
$response = $response->withHeader('Access-Control-Allow-Origin', $allowedOrigin);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user